Skip to content
Digital Security Consulting

HR or operations lead

“Someone left months ago and we think they still have access”

Request a consultation Typical timeline: Audit within a week, remediation immediately after

Does this sound familiar?

  • Nobody has a definitive list of systems staff can log into
  • Shared passwords are in a spreadsheet, a group chat, or somebody's head
  • A departure happened quickly and offboarding was informal
  • Former staff appear in your billing as active licences
  • The person who left set up the hosting, the domain, or the accounting software

What it costs to ignore

Former-employee access is one of the most common causes of data loss in small businesses, and it is almost never sophisticated — it is a login that was never disabled. It is also the hardest to defend afterwards: if data leaves through valid credentials you forgot to revoke, insurers and regulators treat that as a failure of basic control, not as a sophisticated attack.

How the engagement runs

  1. 1

    Inventory every system

    Email, file storage, accounting, CRM, hosting, domain registrar, payment processors, social accounts, VPN, building access. Most organisations are surprised by the length of this list.

  2. 2

    Map who actually has access

    Including service accounts, API keys, saved sessions, forwarding rules and recovery contacts — the places access quietly persists after the obvious account is disabled.

  3. 3

    Revoke and rotate

    Disable individual accounts, rotate every shared credential, revoke API tokens and app passwords, and remove stale forwarding and delegation rules.

  4. 4

    Eliminate shared logins

    Shared passwords make offboarding impossible by design. Named accounts with defined roles mean removing one person is a single action.

  5. 5

    Write the offboarding checklist

    A one-page process HR can run on the last day without needing technical help, so this never becomes a project again.

The unglamorous breach

The breaches that actually hurt small businesses are rarely sophisticated. They are a login that was never turned off.

A designer who still has the social media password. A bookkeeper whose accounting access was never removed. A developer who set up the hosting under their own personal account. None of it malicious — just never closed.

Why it is hard to defend afterwards

If data leaves through credentials you forgot to revoke, that is not treated as a clever attack. Insurers, regulators and clients all see the same thing: a basic control that was not operated.

Under Quebec’s Law 25, if personal information is involved, you are into notification obligations — for an incident that would have been prevented by a checklist.

The outcome

An inventory of every system and who can reach it. Everything stale revoked and verified. Shared passwords rotated into a manager with named accounts. And a one-page checklist HR can run on somebody’s last day without calling anyone technical.

It is a small engagement. It closes one of the largest and most common exposures a business has.

What you get

  • A complete inventory of systems and who can reach them
  • All departed-staff access revoked and verified
  • Shared credentials rotated and moved into a password manager
  • Forwarding rules, API tokens and recovery contacts cleaned up
  • A one-page offboarding checklist HR can run unaided

Frequently asked questions

We disabled their email. Is that not enough?

No, and this is the gap that catches most businesses. Access persists in places that survive the mailbox being disabled: saved browser sessions, app passwords, API tokens, mail forwarding rules set up beforehand, shared credentials they still know, recovery phone numbers pointing at their device, and third-party services that never used your email login at all.

What if they set up our hosting or domain themselves?

That is a serious and surprisingly common situation. If a former employee is the registrant of your domain or the owner of your hosting account, they hold real leverage over your business. Recovering ownership is a documented process with each provider, and we handle it — but it is far easier while the relationship is still cordial.

Is it worth doing if they left on good terms?

Yes, and the reason is not distrust. Their old credentials still exist and are still valid; if they are ever reused or breached elsewhere, that is now your exposure. The control is about closing an open door, not about the person who walked through it.

How do we make this easier next time?

Stop sharing logins. Named accounts with role-based permissions mean offboarding is one action instead of an archaeology project. A password manager with a company vault is the single highest-return change most small businesses can make here.

Services involved

Cybersecurity

Incident response, ransomware recovery, and hardening that holds up under audit.

Learn more

Infrastructure & Backup

Servers, clusters and backups designed so that failure is survivable and boring.

Learn more

Tell us what is breaking — or what you are trying to build.

You get a senior engineer on the first call, not a salesperson. If we are not the right fit, we will say so and point you somewhere better.

Active incident? Write “URGENT” in your message and we prioritise it.